
AS Metabox Security & Risk Analysis
wordpress.org/plugins/as-metaboxAs Metabox Easy To Use WordPress Metabox Framework.
Is AS Metabox Safe to Use in 2026?
Generally Safe
Score 100/100AS Metabox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "as-metabox" plugin v1.0 presents a mixed security posture. On the positive side, it exhibits no known historical vulnerabilities and utilizes prepared statements for all SQL queries. It also implements nonce checks for its AJAX handlers and has a relatively small attack surface with no shortcodes, cron events, or REST API routes. However, significant concerns arise from the static analysis. The plugin uses the `unserialize` function twice, which is a known source of critical vulnerabilities if not handled with extreme care, especially when processing user-controlled data. Furthermore, only 13% of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis reveals two high-severity unsanitized flows, directly correlating with the identified dangerous functions and potential for XSS.
Key Concerns
- Dangerous function: unserialize used twice
- Output escaping is poor (13% proper)
- High severity taint flows detected (2)
- No capability checks on AJAX handlers
AS Metabox Security Vulnerabilities
AS Metabox Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
AS Metabox Attack Surface
AJAX Handlers 3
WordPress Hooks 5
Maintenance & Trust
AS Metabox Maintenance & Trust
Maintenance Signals
Community Trust
AS Metabox Alternatives
Country & Phone Field Contact Form 7
country-phone-field-contact-form-7
Add country drop down with flags and phone number with country phone extension fields in contact form 7.
Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation
gs-logo-slider
Logo Slider: The best responsive plugin for Logo Showcase, Logo Carousel, and displaying clients' logos. Includes shortcode generator with preview!
Site Offline Or Coming Soon Or Maintenance Mode
site-offline
Site Offline plugin manage your WordPress website in under construction or maintenance mode or coming soon or landing page.
Quick Adsense
quick-adsense
Quick Adsense offers a quicker & flexible way to insert Google Adsense or any Ads code into a blog post.
Hide Dashboard Notifications
wp-hide-backed-notices
Warnings and notices can be helpful for developers as they notify them for debugging issues with their code. Though these notices can be sometimes inf …
AS Metabox Developer Profile
5 plugins · 70 total installs
How We Detect AS Metabox
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/as-metabox/assets/css/font-awesome.min.css/wp-content/plugins/as-metabox/assets/css/jquery-ui.min.css/wp-content/plugins/as-metabox/assets/css/animate.css/wp-content/plugins/as-metabox/assets/css/as_main.css/wp-content/plugins/as-metabox/assets/js/as_main.js/wp-content/plugins/as-metabox/assets/js/as_main.jsas-metabox/assets/css/font-awesome.min.css?ver=as-metabox/assets/css/jquery-ui.min.css?ver=as-metabox/assets/css/animate.css?ver=as-metabox/assets/css/as_main.css?ver=as-metabox/assets/js/as_main.js?ver=HTML / DOM Fingerprints
as-metabox-group-wrapperas-metabox-group-contentas-metabox-group-itemas-metabox-tabs-nav-wrapper<!-- as-metabox --><!-- /as-metabox --><!-- as-metabox-tabs-nav --><!-- /as-metabox-tabs-nav -->+2 moredata-formatdata-field-typeas_meta_local